ENISA Threat Landscape 2026 analyzes 8,257 incidents that affected the European Union in 2025. The most cited figures will probably be these: DDoS accounts for 51.3% of incidents, while ideologically motivated activity accounts for 57.3%. In my opinion, the most important indicator can be found in a note below one of the charts: of the 941 malicious events reported by Member States under NIS2 for 2025, approximately half had the declared root cause of “unknown”.
We measure visibility, not reality
The report transparently acknowledges its limitations:
- For unauthorised access incidents, the initial intrusion vector was identified in only 5.2% of cases.
- Espionage campaigns generally come to light six months to four years after they occurred.
- Of the DDoS claims made by hacktivists analyzed by ENISA between July and November 2025, only 23.8% could be independently confirmed.
The report therefore describes what European defenders can see. The difference between that and what is actually happening depends largely on detection and forensics capabilities.
What the data nevertheless shows
- People are the primary target, and identity is the entry point. Phishing accounts for 77.8% of social engineering techniques in ENISA’s data. However, the most effective campaigns went beyond email:
- Attackers called employees posing as IT support, in order to obtain single sign-on credentials and MFA codes.
- They convinced users to approve authentications through legitimate flows (device-code phishing).
- Infostealers collected session cookies, which attackers used to reuse already authenticated sessions.
ClickFix, the technique in which the user is convinced to run malicious commands themselves in order to “fix” a fake error, was frequent throughout the year. Phishing-resistant MFA stops real-time credential phishing, but device-code phishing and stolen session cookies each require their own controls.
- Data theft is becoming the primary leverage in ransomware. Among the techniques publicly reported for the most active groups, exfiltration appears much more frequently (73.3%) than encryption (13.7%). Encryption has not disappeared, but backups do not protect against the threat of data publication. In addition, operators are increasingly equipping their toolkits with tools that disable endpoint security solutions.
- The perimeter remains a weak link. Where the intrusion vector was known, 60.4% of cases involved exploitation of a vulnerability, with internet-facing systems well represented. More than 48,000 new CVEs were published in 2025, so prioritizing based on evidence of active exploitation (CISA KEV, ENISA EUVD) matters more than severity scores.
Attacker speed, detection latency
ENISA notes that in 2025 AI mainly helped attackers improve existing techniques. For 2026, the report points to the first indications of malware using generative AI at runtime and mentions a reported case of AI-assisted cloud intrusion that obtained administrative access in eight minutes. Examples from Romania, however, show that, for now, the main problem is not attacker speed, but detection latency.
Romania: the same lessons
In December 2025, attackers compromised approximately 1,000 IT systems at the National Administration “Apele Române”, using BitLocker, the native Windows functionality, to encrypt files. The way they entered the network was not publicly disclosed.
In July 2026, the attack on the National Agency for Cadastre and Land Registration (ANCPI) followed almost step by step the pattern described by ENISA:
- Initial access. According to DNSC, the attacker exploited a vulnerability known since 2021 on a publicly exposed machine that handled authentication for the agency’s payment platform.
- Privilege escalation. A reused administrator password then gave the attacker access to the central virtualization console.
- Double extortion. Data was copied to an external server before the systems were wiped and encrypted.
The impact was nationwide: notaries could not authenticate documents, and banks could not grant mortgage loans until e-Terra was brought back online, starting on August 11, 2026.
In the same month, the National Administration of Penitentiaries also announced a ransomware attack on several workstations and servers.
ENISA warns about attacks that obtain administrative access within minutes. At ANCPI, the attacker did not need speed. The attack was discovered during routine maintenance activities, approximately 86 hours after the initial access. The server from which the attack originated had been deleted along with the logs needed to reconstruct the attack.
DNSC described the attack as not being particularly sophisticated. The warnings existed: according to CyberInt, the compromises and critical vulnerabilities identified as early as 2021 had been communicated to ANCPI management.
Conclusion
The report and these incidents, taken together, lead to a clear conclusion: in Romania, the deficit has less to do with threat intelligence and more to do with execution. In the ANCPI case, the attacker did not need AI or zero-days. An unpatched internet-facing system, a reused password, and permissive access rules on the internal network were enough.
The same weaknesses explain why so many incidents end with an unknown root cause. If a system is not monitored and its logs are not retained, the incident cannot be explained afterward, let alone prevented the next time.
The priorities follow directly from this:
- Visibility into exposure. Applying security updates to internet-facing systems based on active exploitation and starting from the assumption of compromise when a known vulnerability has remained exposed for a long time.
- Credentials as infrastructure. Unique administrator passwords, phishing-resistant MFA, and separate privileged accounts, especially on virtualization and identity platforms.
- Monitoring critical systems, as a priority. Critical systems should be included first in the monitoring scope, not last.
- Preserving evidence. Logs must be stored separately from the systems they describe, with sufficient retention to reconstruct an attack.
Under NIS2, management bodies must approve and oversee these measures and can be held accountable for failing to implement them. The ANCPI case shows what happens when these measures exist on paper, but not in practice.
If you need support, we are here.